Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in XWiki platform - CVE-2023-45134
Published: October 25, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to execute arbitrary actions with the rights of the user opening a malicious link.
The vulnerability exists due to improper neutralization of script-related HTML tags in the create page form via template provider when processing a selected template provider during document creation. A remote user can create a malicious template provider and send a crafted URL to execute arbitrary actions with the rights of the user opening a malicious link.
User interaction is required to open the crafted link, and exploitation depends on the privileges of the user who opens it.